Skip to main content
TAKE INTERESTAI that adapts to your systems, your rules, and you.

Legal

Privacy Policy

Last updated: October 1, 2026

1. Who We Are

Take Interest Inc. ("Take Interest," "we," "our," or "us") operates the products and services described below. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our products and services, including the Take Interest workspace, GuardClaw security platform, the Pantry Kitchen Journal iOS app, Felt Weather, Askwell, and our website at takeinterest.ai (collectively, the "Services").

Each of our consumer apps has its own privacy details, set out in Section 2 below. Where an app's section describes a practice that differs from the general company sections in this policy, the app's section governs for that app.

Statements in this policy describe what we do on the date at the top of the page. Section 3.3 covers what may change and what stays yours across any change.

2. Product-Specific Privacy

This section covers the privacy practices of our individual apps. The company-wide sections that follow (collection, third parties, rights, CCPA, GDPR, retention, and contact) apply to all of our Services in addition to what each app section describes.

Askwell

Askwell is a question-coaching app made by Take Interest Inc. You type a rough question, Askwell finds the missing signal and hands back a sharper one, and it keeps a receipt of the change. This section covers the Askwell iPhone app.

Sign-in is required: Askwell asks you to sign in with Apple or Google before you use it. Sign-in runs through Firebase Authentication, a Google service we use as our authentication provider. When you sign in, your account gets a name, an email address, and a user id. We use these only to run your account, they are linked to your identity, and they are not used to track you.

On your device: your question text, the scores Askwell computes, and the receipts you save are created and stored on your device. A receipt is the proof note Askwell keeps after you sharpen a question: the before and after, the score, the signals, and a next-rep prompt.

Analytics is off by default: Askwell can record anonymous usage analytics through Firebase Analytics (Product Interaction) to help us improve the app. It is off by default and turns on only if you enable it in Settings. When it is on, it records how the app is used, such as which screens you open, and it does not include your question text. It is linked to your identity and is not used to track you.

Account deletion and sign-out: you can sign out any time. You can delete your account from Settings, which removes the account record and clears the local data on your device.

No tracking: as of July 2026, Askwell has no advertising identifier, runs no ad network, and does no cross-app or cross-site tracking. The app's privacy manifest declares tracking off. Because Askwell collects the account fields above and the opt-in analytics, its App Store privacy label reads Data Is Collected.

Askwell signs you in with Apple or Google so your saved questions stay tied to your account. Sign-in gives your account a name, an email, and a user id, used only to run your account and not to track you. Your question text, scores, and saved receipts are created and stored on your device. Anonymous usage analytics through Firebase is off by default and turns on only if you choose it in Settings. You can sign out or delete your account any time. The App Store privacy label reads Data Is Collected for the account fields and the opt-in analytics, with tracking off.

Felt Weather

Felt Weather is made by Take Interest Inc. This section covers the Felt Weather apps on iPhone, Apple Watch, and Mac and their companion surfaces.

Sign-in is required: signing in with Apple or Google is required to use Felt. Sign-in runs through Firebase Authentication, so the app holds your email, your name, and an account identifier. These are used only to sign you in and keep you signed in. We do not store your weather forecasts or your device calendar on our servers. When you create or join a shared plan, we do store that plan on our servers: the activity, the general area, the day, and your comfort curve, which is what lets everyone in the plan see a shared view. Only people in that plan can read it.

On your device: raw calendar reads and live weather are processed on your device. Saved places, route drafts, future plans and preferences can be stored in your account record, and shared plans and chat are stored separately, as described below. If you enable spoken features, composed text can include a calendar event title and is sent to our voice service. Widgets, Live Activity, and Apple Watch receive only a redacted day summary needed to display the feature. Apple Watch does not sign in on its own.

Weather and spoken requests: your coordinates go to Apple's WeatherKit so it can return the forecast, and to Apple Maps when you search a place or ask for a route. When Felt speaks a line out loud, the composed text is sent through Firebase to Google Cloud Text-to-Speech and comes back as audio. If the sentence mentions something Felt read from your calendar, such as an event title, that wording travels with it. Raw calendar records are not uploaded by account sync. A line Felt has spoken before can replay from a cache without a new synthesis request. Felt speaks only when you ask it to or when you have turned a spoken feature on.

Cross-device sync (Felt Weather 1.4 and later): signing in keeps your saved work in step across your own devices. Felt stores one account-linked record in Google's Cloud Firestore containing saved place labels and unrounded map coordinates, route favorites and drafts, future plans with their notes and reminder bookkeeping, and app preferences such as units, comfort settings, activity order, and motion settings. Saved Home and Work places and chosen route endpoints can describe your precise location. A security rule restricts this record to your signed-in account. Raw calendar records and live weather forecasts are not fields of this synced record. Synced comfort settings customize the activity windows Felt suggests.

Location: when you enable location access, Felt uses your device location for local weather, the city label and route planning. Weather and map requests are sent to Apple as described below. Places and route endpoints you save can be retained with precise coordinates in your account-linked Firestore record, including coordinates that describe your location. This saved-coordinate path is separate from request-time weather and map processing and from the general geography Google Analytics derives when you opt in. You can revoke device location permission in Settings; doing so does not by itself delete places or routes you already saved.

Severe-weather alert details (Felt Weather 1.12 and later): when Apple's weather service reports an active government alert for your area, Felt asks the National Weather Service's public alert feed (api.weather.gov, a US government service) for that alert's official timing and instructions. This request uses coordinates rounded to two decimal places and an app-identifying header, without an account identifier or cookie. On a day with no active alert, this enrichment request does not happen. It is separate from the saved-coordinate sync described above.

Calendar: calendar access lets Felt line your day up with the forecast. Reads happen locally on your device. Any change Felt makes to your calendar happens only when you confirm it. Calendar access is off until you tap Connect Calendar, and you can revoke it any time in Settings on your device.

Plan chat: a shared plan has a chat room, so the people on that plan can talk in the app. Messages are stored on our servers in Google's Cloud Firestore, and we can read them, because that is what lets us moderate them. Plan chat is not end-to-end encrypted, and the in-app agreement you accept before you post says the same. Messages are text only, capped at 2,000 characters, with no photos, no files, and no voice notes. Everyone on the plan sees your messages and the display name on your account. Nobody outside that plan can read them, and a security rule enforces it.

Chat moderation and safety: plan chat is for people 17 and older. Felt checks a message on your device before it sends, and blocks the ones that break the community agreement. Anything that gets through can be reported by anyone on the plan, and we review reports and remove content or eject an abusive account within 24 hours. You can block anyone you share a plan with, which hides them from you both ways. Reports are kept as their own records so we can act on repeat behavior, and a report record stays even if the message it names is deleted. We use plan chat only for moderation, safety, and keeping the feature working, and it is not used to train models, as described in Section 3.4.

Chat retention: shared plans receive an expiration time seven days after the later of the plan day or its creation. An enabled nightly retention job is scheduled to remove expired plans and their messages. This automatic processing can be delayed by failures or incomplete sweeps; a schedule is not a guarantee that every record has already been deleted. You can request deletion of your own messages in the app. Account deletion triggers the removal of account-linked content, while moderation, billing and infrastructure records have separate retention and may remain after the account is deleted.

Weather, maps, and routes: to show you the forecast, Felt sends your coordinates to Apple's WeatherKit, which returns the weather. When you search for a place or ask for a route, Felt sends that query to Apple Maps through MapKit. Apple processes both under Apple's privacy policy, and we do not keep a copy. If you tap a Google Maps or Waze handoff, the route opens in the app or site you chose, and that handoff is user-initiated. Aurora forecasts come from NOAA's Space Weather Prediction Center and close-approach data from NASA's Jet Propulsion Laboratory, which are read-only feeds that receive no personal data.

Subscriptions and purchase history: subscription verification sends Apple's signed StoreKit transaction proof to a Firebase service. We retain derived entitlement information with your account, including the product, access tier, expiry and original transaction identifier, to provide access and prevent misuse. Apple subscription notifications also produce subscription lifecycle records used for billing and subscription analytics. Those lifecycle records are retained separately and are not removed by the account-content deletion cascade. When Help improve Felt is enabled, a product-specific purchase event also contributes to product analytics. These handlers do not receive your payment card or bank account details.

Plan notifications: when you enable chat notifications, an APNs device token is stored under your signed-in account with platform, time zone and update time so the service can deliver notifications. This account-linked device identifier supports app functionality independently of product-analytics consent.

Analytics and tracking (off until you turn it on): Help improve Felt starts off and controls the app's product-analytics relay and Google Analytics for Firebase collection. When enabled, the relay sends allowlisted usage events, platform, app version, timestamp and a random install handle through our server to Mixpanel; no Mixpanel code runs in the app. Google Analytics receives separate allowlisted product events and funnel parameters such as screen name, source, action and product id, along with its own app-instance identity and standard app/device metadata. The configured Google Analytics property also collects general geography such as city-level location. Custom event parameters exclude account email, Firebase account UID, receipt and transaction identifiers, coordinates, message content and other free-form text; that allowlist does not describe every automatic SDK field. The build excludes advertising-identifier support. The App Store privacy declaration treats measurement identifiers, interactions and general geography as linked through account or device identity, with tracking off under the current configuration. Turning Help improve Felt off stops these product-analytics paths and resets local measurement state; it does not erase previously retained server history. Account, purchase, notification and security processing operate independently of this switch.

The install handle: when you enable Help improve Felt, the app creates a random UUID for its relay counts so Mixpanel can group usage over time. It is not derived from your Apple ID, account, advertising identifier, device serial number or hardware values. Google Analytics does not receive that relay handle and uses a separate app-instance measurement identity. Turning the switch off clears the local relay handle and resets local Google Analytics measurement state; the relay handle also rotates every 180 days. These local changes do not establish deletion or de-identification of historical data held by a provider.

Infrastructure logs: product-analytics relay requests can generate cloud request metadata, including the sending IP address. The project's default log bucket is configured for 30-day retention; required audit logs have a separate 400-day retention. No logging exclusion for the relay was present in the inspected project sink configuration. These infrastructure records are separate from custom analytics parameters and can remain after local measurement state is reset.

How your plans turn out (on your device): when you book a window through Felt, the app keeps a short record on your device of how that window scored when you booked it, how the score moved as the day got closer, and whether you kept the plan or undid it. It holds the most recent 200 and older ones fall off. Each entry carries the kind of activity, the times, the comfort scores, and the kept-or-undone outcome. It has no event titles, no place names, and no location. This record stays on your device and is not sent to any server we operate, so we have not seen yours. We use it to work out whether a future version of Felt could tell you when a booked plan is turning, which is a feature we have not built. There is no switch for this one today, which is why it is written here, and we are adding one. Removing the app clears it.

Retention and controls: your account details (email, name, and identifier) are kept through Firebase Authentication for as long as your account exists. On 1.4 and later, your synced record is kept in Cloud Firestore for as long as your account exists. Plan chat messages are stored separately from that record and are covered above. You can sign out from the profile chip, which also stops sync. You can ask us to access or delete the account data tied to your sign-in by emailing the address in Section 14. Deleting your account also removes the synced record. Removing the app clears the on-device data.

Felt Weather uses Apple or Google sign-in through Firebase Authentication. Saved places and chosen route endpoints, including Home and Work, can sync with precise coordinates to your account-linked Cloud Firestore record alongside plans and preferences. Those saved coordinates can describe your location. Synced comfort settings personalize suggested activity windows. Raw calendar records and live weather forecasts are processed locally, but composed spoken text, including a possible calendar event title, goes through Firebase to Google Cloud Text-to-Speech. Shared-plan messages are stored for coordination and moderation and are not end-to-end encrypted; an enabled nightly job is scheduled to remove expired plans and messages, with failures potentially delaying processing. Notification tokens are stored under your account to deliver chat notifications. Signed StoreKit proof is processed for subscriptions, derived entitlements are retained with your account, and separate subscription lifecycle records support billing analytics and remain outside account-content deletion. These handlers do not receive card or bank details. Help improve Felt defaults off. When enabled, Mixpanel receives allowlisted relay events with a random install handle, while Google Analytics receives separate product events, its own app-instance identity, standard app/device metadata and general geography. Custom analytics parameters exclude account email, Firebase account UID, receipt or transaction identifiers, coordinates and free-form content. Measurement identity is classified as linked to the device, with tracking off under the current configuration. Opt-out resets local measurement state without erasing retained server history. Account, subscription and notification processing is separate from this switch. You can sign out, revoke device permissions or request account deletion; operational and billing records have separate retention.

Pantry Kitchen Journal

Pantry Kitchen Journal ("Pantry") is made by Take Interest Inc. This section covers the Pantry iOS app. Your kitchen data stays yours.

On your device or your private iCloud: Pantry reads the grocery receipts you photograph or import and turns them into a kitchen inventory with shelf-life estimates and recipe options. All of that processing happens on your device using Apple's on-device text recognition. Your receipts, items, and consumption history do not reach us or any third party. If your device is signed into iCloud, Pantry stores its data in your private iCloud database so your kitchen syncs across your own devices. That data is controlled by your Apple account and readable only by you. If iCloud is off, everything stays on your device.

Accounts are optional: you can use all of Pantry without an account. If you choose to sign in with Apple or Google, the app sends the provider sign-in token to a Take Interest verification service, which checks the token is genuine and sends back a confirmation. The token carries no kitchen data, and the service stores nothing. We receive your verified email address, and your name if the provider shares it. Your account record lives on your device in the iOS Keychain. It does not enter iCloud Keychain and it does not reach our servers. You can sign out or delete your account inside the app at any time (Account then Delete account).

What we collect: we do not collect your receipts, pantry items, recipes, consumption history, grocery habits, or household content. If you sign in, we process your verified email address and optional name only for account sign-in.

Diagnostics (on by default, one tap to turn off): two helpers are on by default so we can fix crashes and see which features help. Crash reports (Sentry) send a technical stack trace when the app crashes. Usage analytics (Mixpanel) counts a short, fixed list of actions, such as receipt captured or recipe generated. Diagnostics do not include receipt text, item names, recipe content, email addresses, names, household names, location, advertising identifiers, or IP-based geolocation. Events outside the fixed list are dropped before they leave the device. You can turn either off any time from your Profile page or Settings then Privacy choices, and your choice sticks.

Deleting your data: delete items in the app any time, or delete your account inside the app (Account then Delete account). Deleting the app removes its on-device data. To remove synced data, delete Pantry's data from iCloud in Settings on your device.

Pantry keeps kitchen content on your device or in your own private iCloud. Optional Apple or Google sign-in processes a verified email address and optional name for account access. Crash reporting and Mixpanel usage analytics are on by default when configured, with in-app switches to turn either off. Current diagnostics do not send receipt text, pantry items, recipes, grocery history, household names, email addresses, names, location, advertising identifiers, or IP-based geolocation. If a future release adds advertising, tracking, additional analytics, or other data uses, this policy and the App Store privacy label must be updated before that release ships.

GuardClaw

GuardClaw is the runtime security system for AI agents made by Take Interest Inc. This section covers GuardClaw local runtime behavior (CLI, shell wrapper, MCP server) and optional GuardClaw Cloud features (account, billing, usage, receipts, agent management, and environment management). Take Interest Inc. is the data controller for data collected through GuardClaw cloud services. For customer personal data processed on behalf of your organization, we act as a data processor, and a Data Processing Addendum is available on request at legal@takeinterest.ai.

Account and billing data: email, display name, tenant and workspace identifiers, plus Stripe customer and subscription identifiers and billing events. We do not store payment card numbers, which are handled entirely by Stripe.

Usage, audit, and agent data: decision counts, usage events, receipt metadata, and receipt content hashes. When agent management is enabled, we collect agent identifiers, hostname, operating system, software version, process identifiers, agent state, heartbeat timestamps, CPU and memory usage metrics, runtime duration, failure counts, anomaly scores, and anomaly detection levels. Agent control records include actor user identifiers, actor IP addresses, actions taken, reasons, and acknowledgment timestamps. Environment data covers environment names, status, runtime type, risk scores, agent counts, and security event counts.

Anonymous telemetry (opt-out): the GuardClaw CLI collects anonymous telemetry by default, including decision counts, threat scores, timing, platform, and version. Prompts, commands, file paths, and personal identifiers are excluded. You can disable it at any time with the command guardclaw telemetry disable.

Training data: free tier usage is included in anonymized training data as a condition of the free service, using only anonymized, aggregated detection telemetry with no raw prompts, commands, or PII. On paid plans (Pro and Ultimate), training data collection is consent-based and you may opt out at any time via account settings or the command guardclaw training disable.

Retention and deletion: decision receipts and agent monitoring data are stored indefinitely. Access is limited by plan: Free (1,000 most recent viewable receipts per workspace), Pro (100,000), Ultimate (500,000). Plan quotas limit how many receipts are accessible. They do not limit how many are stored. Account deletion marks the tenant status as deleted, cancels any active subscriptions, and initiates cleanup of account and billing data. Billing records may persist in Stripe per their privacy policy.

Subprocessors: Google Cloud and Firebase (auth, storage, infrastructure), Stripe (billing), Mixpanel (anonymous product analytics on the dashboard, no PII, IP tracking disabled), and Sentry (error and crash reporting, stack traces only, no PII), all in the United States. To exercise your rights for GuardClaw data, contact legal@takeinterest.ai or use the account management features in the dashboard.

Site chat and contact form

Our website at takeinterest.ai has a small questions widget and a contact form. The chat is an automated assistant, not a person, and it answers from a reviewed FAQ set. It runs on our own systems, and no third party reads your messages. Cloudflare Turnstile processes your IP address to block bots, acting as our service provider (see Section 7).

If you leave your contact details, that record is stored so a real person can reply, and it deletes automatically after 180 days. We do not sell your personal information and we do not share it for cross-context behavioral advertising. If you sign in, saving your chat history is optional, requires your separate consent, and is kept until you delete it. You can view, export, or delete it from the widget at any time, or email privacy@takeinterest.ai for any request.

Mailing list

Several pages on takeinterest.ai offer a form to join our mailing list. Giving us your address is entirely optional and nothing on the site requires it. We use it to send occasional updates about what we are building, roughly monthly, and for nothing else.

The list runs on Mailchimp, operated by Intuit Inc. in the United States, acting as our service provider. Two details are worth stating plainly. First, the form posts from your browser straight to Mailchimp rather than through our servers, so Mailchimp receives your email address and your IP address directly, under its own privacy policy. Second, we ask Mailchimp to confirm the address with you before adding it, so that nobody can put you on the list by typing your address into our form.

Every message we send carries an unsubscribe link, and leaving takes one click. You can also email privacy@takeinterest.ai and we will remove you. We do not sell your address, we do not share it for cross-context behavioral advertising, and we do not use it to build an advertising profile.

3. Information We Collect

3.1 Information You Provide

Account Information: When you create an account, we collect your email address and authentication credentials. Authentication may use Firebase Authentication (Google Identity Platform) or equivalent managed identity services. Multi-factor authentication may be required for specific environments.

User-Generated Content: Content you create within our Services, including decision drafts, strategies, evidence notes, frameworks, and other workspace content. We treat all user-generated content as highly sensitive and private.

Contact Information: When you contact us via our contact form, we collect your name, email address, subject, and message content. The form uses Cloudflare Turnstile for bot verification, which may process your IP address and browser signals to validate the challenge. See Section 7 for details.

Mailing List: If you use one of the join forms on our website, we collect your email address and, where the form offers it, a first name. This is optional and separate from everything above. The form posts directly to Mailchimp rather than to our servers, so Mailchimp also receives your IP address. We ask Mailchimp to confirm the address with you before adding it. See the Mailing list section above and Section 7.

3.2 Information Collected Automatically

GuardClaw Telemetry (opt-out): The GuardClaw CLI collects anonymous telemetry by default, including decision counts, threat scores, timing data, platform, and version. Prompts, commands, file paths, and personal identifiers are excluded from this telemetry. You can disable telemetry at any time with guardclaw telemetry disable.

Dashboard Analytics: We use Mixpanel for anonymous product analytics on the GuardClaw dashboard and related product surfaces. IP tracking is disabled. We use these events to understand feature use, reliability, onboarding, and product demand.

Error Diagnostics: We use Sentry for error reporting with heavy redaction. Request bodies, user records, breadcrumbs and file paths are stripped before an event leaves the machine. PII sending is off. We sample 10 percent of performance traces.

Server Logs: Standard server access logs are collected for security and operational purposes. These logs do not contain user-generated content.

GuardClaw Agent Data: When agent management features are enabled, we collect agent identifiers, hostname, operating system, software version, heartbeat timestamps, CPU and memory usage metrics, runtime duration, anomaly scores, and agent control event logs (including actor IP addresses for audit purposes).

3.3 Advertising, Analytics, and What May Change

Take Interest is a business, and how we fund and improve our products will change over time. We would rather set that out here than surprise you with it later.

What we may do. We may run advertising or sponsored placement in our products and on our website. We may use analytics and tracking technologies, including cookies and similar technologies, our own measurement and third-party measurement, to understand how the Services are used and to fund them. We may share data with partners for advertising or measurement, on a consent basis where the law asks for consent. We may offer you the choice to let your data help train our models. We may use data to build and improve features, including features that do not exist yet. What each product collects today is described in Section 2 and Section 3.2, and the free tier collects product usage data to fund and improve the Services.

How a change happens. A change is written into this policy before it starts, and the date at the top of the page moves when it does. A change applies going forward only. Data we already collected under an earlier version of this policy stays under the rules that were in force when we collected it. Where the law asks for consent, we ask before the change applies to you. Where the law asks for an opt-out, the opt-out goes live on the same day as the change.

What holds across every change. Three things hold whatever else we do.

First, training on your content is opt-in. It is its own choice, separate from any other setting, and you can turn it back off.

Second, you can turn data collection off, on any tier, free or paid. A paid tier that collects no product usage analytics stays available as a product choice. Section 8 tells you how, and each product section in Section 2 names the switch for that app.

Third, we do not run covert collection. What we collect is written down here in plain words. We follow United States federal and state privacy law, including the California rights to know, delete, correct, opt out of the sale or sharing of personal information, limit the use of sensitive personal information, and cancel a paid subscription, and the equivalent rights under GDPR and UK GDPR where those apply to you. Section 11 covers California and Section 12 covers Europe.

What we learn in aggregate. We use what we learn across many people from how the Services are used, meaning counts, patterns, and measurements computed over a population rather than about one person. Where we build it, that may also include learning that happens on your device and sends back only a summary rather than your content. We treat learning of this kind as ours to use in improving our products. Content that identifies you or can be traced back to you is used to train models only if you turn training on.

Some account, payment, security, and legal records are processed whatever your settings say, because they are needed to operate the Services, prevent abuse, complete transactions, or meet a legal duty. Turning collection off does not turn those off.

3.4 Model Training

We do not use your User Content, decision drafts, strategies, or other material you create to train machine learning models unless you turn training on. Training is a separate choice you make on its own, and you can turn it back off. This applies to our own models and to third-party models, including Claude, Gemini, and the embedding models the Services use. Where a model provider offers a no-training setting on its API, we use it, and where none exists we hold the same limit by contract and policy. The GuardClaw free tier is the one exception, and its terms say so. If you turn training on, we will say at that moment what goes in and what it is used for, and declining keeps every part of the Services working.

Separately from your content, de-identified and aggregated usage signals, such as anonymous feature counts, are used to improve the Services. Those aggregates do not include your User Content. Section 3.3 describes how we treat aggregate learning. Contact privacy@takeinterest.ai for the current version of this policy or for a copy of an earlier one.

4. How We Use Your Information

We use your information to:

Provide, maintain, and improve our Services. Authenticate your identity and enforce access controls. Communicate with you about your account or our Services. Respond to your inquiries and support requests. Detect, prevent, and address security threats and abuse. Measure usage on the free tier to support product funding and product decisions. Improve our systems in ways that honor the model-training limits in Section 3.4. Comply with legal obligations.

5. Data Storage and Security

Infrastructure: All data is stored on Google Cloud Platform (GCP) in the United States. Data is encrypted at rest using Google-managed encryption and in transit using TLS 1.2+.

Sensitive Data Encryption: OAuth tokens and other highly sensitive credentials are encrypted using managed cryptographic controls and secure secret storage.

Access Controls: Backend services use dedicated service accounts with least-privilege permissions. User access controls may include allowlisting, MFA requirements, and server-side token verification where applicable.

Edge Protection: Public endpoints use edge protections such as rate limiting and request filtering to reduce abuse risk.

6. Data Retention

Account Data: Retained for the duration of your account. Deleted within 30 days of account deletion request.

User-Generated Content: Retained for the duration of your account. You may export or delete your content at any time.

GuardClaw Audit Data: All decision receipts are stored indefinitely. Access is limited by plan: Free (1,000 most recent receipts per workspace), Pro (100,000), Ultimate (500,000). Usage events are retained for operational purposes.

Server Logs: Retained for up to 90 days for security and operational purposes.

Contact Form Submissions: Retained for up to 180 days or until the inquiry is resolved, whichever comes first. Submissions are automatically deleted after the retention period.

7. Third-Party Services

We use the following third-party services as part of our infrastructure:

Google Cloud Platform: Cloud infrastructure, hosting, and authentication. Subject to Google Cloud's Data Processing Terms.

Firebase: Authentication and web hosting. Subject to Firebase Terms of Service.

Stripe: Payment processing (when enabled). Subject to Stripe's Privacy Policy. We do not store credit card numbers on our servers.

Cloudflare: DNS, edge network, and bot verification (Turnstile) for the contact form. Turnstile processes IP addresses and browser signals to distinguish humans from bots. Subject to Cloudflare's Privacy Policy.

Sentry: Error monitoring with heavily redacted data. Default PII sending is off.

Mixpanel: Product analytics for the GuardClaw dashboard, Pantry diagnostic counts, and Felt Weather usage counts. IP tracking is disabled. Pantry sends only allowlisted event names and non-content properties, with no receipt text, pantry items, names, email addresses, household names, or location. Felt Weather sends nothing unless you turn on Help improve Felt, ships no Mixpanel code in the app, and reaches Mixpanel only through our own server, which forwards allowlisted event names with no account or advertising identifier attached, and with the random install handle described in the Felt Weather section above.

Google Analytics for Firebase: product analytics for the Felt Weather app funnel, enabled only through Help improve Felt. The build excludes advertising-identifier support. The service receives allowlisted product events plus its app-instance identity and standard app/device metadata; the configured property also collects general geography such as city-level location. Custom event parameters exclude account email, Firebase account UID, receipts, transaction identifiers, coordinates and free-form text. Google Analytics does not receive the separate Mixpanel relay install handle, and we set no Firebase user id. Its app-instance association still counts as linked device measurement. Subject to Google's Privacy Policy.

Mailchimp (Intuit Inc.): Mailing list for our website updates, in the United States. The join forms post from your browser directly to Mailchimp, so it receives your email address and IP address rather than receiving them from us. We request confirmed opt-in before any address is added, and every message carries an unsubscribe link. Subject to Intuit's Privacy Policy.

Apple and Google: Optional Pantry sign-in providers. Pantry receives the verified account information the provider returns, such as email address and, when shared, name.

We do not share user-generated content with any third-party service for their independent use. For our own model training and system improvement, see Section 3.4.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

Access: Request a copy of the personal information we hold about you.

Correction: Request correction of inaccurate personal information.

Deletion: Request deletion of your personal information and account.

Export: Request an export of your data in a portable format.

Restriction: Request restriction of processing of your personal information.

Objection: Object to processing of your personal information.

Opt Out: Turn off product usage analytics and opt out of any sale or sharing of personal information where state law provides that right.

Cancel: Cancel a paid subscription or paid tier as described in the product or billing flow.

To exercise any of these rights, contact us at privacy@takeinterest.ai. We will respond within 30 days.

9. International Data Transfers

Our Services are hosted in the United States. If you access our Services from outside the United States, your information will be transferred to, stored, and processed in the United States. We implement appropriate safeguards for international data transfers in compliance with applicable data protection laws.

10. Children's Privacy

Our Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information promptly.

11. California Privacy Rights (CCPA)

If you are a California resident, you have the right to know what personal information we collect, request deletion of your personal information, correct inaccurate information, opt out of sale or sharing, limit certain sensitive data uses where applicable, cancel paid subscriptions as required by law, and not be discriminated against for exercising your privacy rights. If we add advertising or consent-based data revenue that counts as sale or sharing under California law, we will provide the required notice and opt-out control.

12. European Privacy Rights (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, our legal basis for processing your personal information is: contractual necessity (to provide our Services), legitimate interests (security, fraud prevention, service improvement), consent (where required), and legal obligation (compliance with applicable laws). You have additional rights under GDPR including data portability and the right to lodge a complaint with a supervisory authority.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We notify you of material changes by posting the updated policy on our website and moving the "Last updated" date at the top of the page. Your continued use of our Services after the effective date of changes constitutes acceptance of the updated policy.

A change applies going forward only. Data we already collected under an earlier version of this policy stays under the rules that were in force when we collected it. If you want a copy of an earlier version of this policy, email privacy@takeinterest.ai and we will send it to you.

Felt Weather factual corrections on October 1, 2026. We corrected the Felt section and its summary to distinguish local calendar and weather processing from account-linked saved coordinates and content, disclose retained subscription proof and lifecycle records, describe notification tokens and personalized comfort suggestions, and separate custom analytics parameters from Google Analytics device identity and general geography. We also replaced the obsolete statement that the plan purge was not running with its verified enabled schedule, without promising successful deletion of every record. This corrects descriptions of existing behavior and declarations; it does not enable collection, advertising, tracking or model training or change the rules for previously collected data.

What changed on July 26, 2026, and why. We reviewed every privacy claim on this site against the code that actually ships, and several were stronger than the code could support. We corrected them and we would rather say what changed than quietly swap the wording.

We removed absolute wording such as "never" from claims we cannot hold open forever, and replaced it with what is true today, dated, and scoped to the product it describes. Section 3.3 is new and sets out what may change in how we fund the products, including advertising, analytics, consent-based data sharing, and opt-in training, along with the three things that hold across any change. Section 3.4 now says plainly that training on your content happens only if you turn training on, replacing a flat statement that we would never do it.

In the Felt Weather section we added plan chat, which was a shipped feature this policy had never mentioned, including the fact that we store those messages and can read them for moderation. We added the on-device record Felt keeps of how your booked plans turn out, which had no disclosure and no switch. We corrected the claim that your weather and calendar stay on your device by naming the two things that do leave it. And we corrected a sentence saying a usage count could not be traced back to you, because our cloud provider writes its own request log that records the sending IP address.

14. Contact Us

If you have questions about this Privacy Policy or our privacy practices, contact us at:

Take Interest Inc.
Email: privacy@takeinterest.ai